Information We Collect
Information you provide
When you create a ProductPen account, we collect:
- Name and email address — used for account creation and communication
- Payment information — processed securely by Stripe (we never store card details)
- Product content — product names, descriptions, and details you enter for AI generation
Information collected automatically
When you use ProductPen, we automatically collect:
- Usage data — features used, generations created, pages visited
- Device information — browser type, operating system, screen size
- Log data — IP address, access times, referring URLs
We use cookies and similar technologies for authentication, preferences, and analytics. See Section 06 for details.
How We Use Your Information
We use your information to:
- Provide the service — generate, improve, and audit product descriptions
- Process payments — manage subscriptions and billing through Stripe
- Send essential communications — account confirmations, password resets, billing receipts
- Improve ProductPen — analyze usage patterns to build better features
- Provide support — respond to your questions and resolve issues
We do not use your information to:
- Sell your personal data to third parties
- Send unsolicited marketing emails (unless you opt in)
- Use your product descriptions to train AI models without explicit consent
AI Processing
ProductPen uses Anthropic's Claude AI to generate product descriptions. When you use our generation features:
- Your product details are sent to Anthropic's API for processing
- Anthropic processes inputs according to their own privacy policy and data retention practices
- Generated outputs are stored in your ProductPen account
- We do not share your inputs or outputs with other users
Anthropic's privacy policy governs their handling of data: anthropic.com/policies/privacy
Data Storage and Security
Where your data is stored
Your data is stored securely using Supabase infrastructure with:
- Encryption at rest — all stored data is encrypted
- Encryption in transit — all data transfers use TLS/SSL
- Access controls — strict role-based access to databases
- Regular backups — automated database backups
Data retention
- Active accounts — data retained for the lifetime of your account
- Deleted accounts — data removed within 30 days of account deletion
- Audit tool data — anonymous audit submissions retained for analytics; personal data (if any) removed within 90 days
Data location
Our infrastructure providers (Supabase, Vercel) operate servers in the United States and European Union.
Third-Party Services
We use the following trusted third-party services:
We carefully select providers with strong privacy practices. Each provider processes data according to their own privacy policies.
Your Rights
You have the right to:
- Access — request a copy of all personal data we hold about you
- Correct — update or fix inaccurate personal information
- Delete — request permanent deletion of your account and data
- Export — download your data in a portable format
- Object — opt out of non-essential data processing
To exercise any of these rights, contact us at privacy@productpen.xyz. We will respond within 30 days.
For EU/EEA residents (GDPR)
You have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability and the right to lodge a complaint with your national supervisory authority (e.g., the ICO in the UK, CNIL in France, or your local data protection authority).
For California residents (CCPA)
Under the California Consumer Privacy Act (CCPA), you have the right to know what personal data we collect, request deletion of your data, and opt out of data sales. We do not sell personal data.
Children's Privacy
ProductPen is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@productpen.xyz and we will promptly delete the information.
International Data Transfers
If you are located outside the United States, your data may be transferred to and processed in the United States where our infrastructure providers operate. We ensure appropriate safeguards are in place for international transfers, including compliance with applicable data protection regulations such as the GDPR for users in the European Economic Area.
Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes:
- We will notify you via email
- We will update the "Last updated" date at the top
- We will post a notice on our website
Continued use of ProductPen after changes constitutes acceptance of the updated policy.
Contact
Questions or concerns about this privacy policy?
- Email — privacy@productpen.xyz
- Response time — Within 24 hours on business days
For general support, visit our contact page or use the chat widget on any page.